Belnet, Belgium’s national network for higher education, research and public services, detected a security and privacy incident in its infrastructure on September 24, 2026. The organisation says the intrusion resulted from exploitation of a zero-day vulnerability affecting technology supplied by Fortinet.
Belnet says it fixed the vulnerability on September 25 at 08:10, engaged the Centre for Cybersecurity Belgium and informed the competent authorities. Fortinet published advisory FG-IR-26-175 about the vulnerability. Belnet’s investigation continues to establish the incident’s scope.
Incoming emails were copied
Belnet established that emails processed by the affected infrastructure between July 22, 2026 and the morning of September 25 were copied and transferred to external infrastructure. The scope includes incoming messages addressed to domains owned by Belnet, along with sender details, message content and attachments.
The organisation has informed its customers and says it is continuing to identify other potentially affected parties. People involved should rely on direct communications from Belnet for details about their own situation.
FileSender and FedSender links
Download links generated and sent directly by FileSender and FedSender during the affected period may also have allowed access to associated files. As a precaution, Belnet disabled links that were still active and transfers created during that period on September 29. Senders and recipients received an automatic notification.
Belnet says password-protected or authenticated transfers are not affected in this way, provided the password was not included in an upload comment. A sender who still needs to share a file should create a new transfer; a recipient should ask the sender to create it again.
Guestroam accounts and impersonation risk
Guestroam accounts generated through Belnet’s service are also included in the published scope. Copied emails and potentially accessible files may contain professional or personal context. This creates a risk of more convincing phishing, but does not prove that a fraud campaign has already used the data.
Verify unexpected requests through a channel you already know, especially if they refer to a conversation, transfer or Belnet account. Do not share a password, authentication code or banking detail in response to an unexpected email or call.
Steps for organisations
Institutions using Belnet services should review emails received and transfers created between July 22 and September 25. Identify sensitive files that may have been shared by link, check whether each transfer met Belnet’s stated protection conditions, and ask the sender to recreate any sharing that is still needed.
Fortinet administrators should consult advisory FG-IR-26-175 to determine whether their equipment and version are affected, then apply the vendor’s security measures. Fixing the vulnerability and assessing potentially exposed emails and files are separate tasks.
The Soclyde connection
This incident concerns email and file-transfer infrastructure; Soclyde does not protect Belnet, FileSender or FedSender. Soclyde is a local-first password and access manager: its encrypted vault helps a user organise their own credentials on their devices. It does not replace email system security or controls over file transfers.
Takeaway
Belnet confirms incoming emails were copied between July 22 and September 25, and that some FileSender and FedSender links may have allowed access to files. Guestroam accounts are also in scope. Institutions should review their communications and follow Belnet’s and Fortinet’s guidance.
To organise your team’s access details, read our guide to local-first password managers.



